App Store 4.7.2 rejection: Native API access from hosted software

By The Draftbit team · Updated
Sources checked

This guide is for iPhone and iPad apps exposing device or platform capabilities to hosted mini apps, plugins, or other software.

A JavaScript bridge can give hosted software access to native capabilities. Apple’s 4.7.2 requires prior permission before the app exposes native platform APIs or technologies to software offered under 4.7.

Inspect the bridge

Ask your developer to list the native methods available to hosted code, including methods added by dependencies. We’d test what a hosted item can invoke, rather than rely only on the list of capabilities shown in your documentation.

Match access to Apple’s permission

Remove unapproved exposure or obtain the required prior permission. Keep evidence of what Apple approved and compare it with the shipped implementation. Consent from the user is a separate issue; it doesn’t replace Apple’s permission under this clause.

Test the corrected bridge with permitted and rejected method calls in a safe development environment. Give Apple the capabilities exposed, the approval supporting them, and a reviewable example. Also check 4.7.3 for sharing user data and privacy permissions.

Messages this guide can help with

App Store 4.7.2 rejection; app store 4.7.2 denial; Guideline 4.7.2; Native API access from hosted software

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit your iPhone or iPad app for review